LM
Lucas Mülling
— On the schedule —
Shipping OpenSSL downstream and its challenges
As distribution maintainers for openssl, we act as system integrators - we test and try to maintain compatability between produciton systems. Shipping secure, compatible cryptography at scale is a constant tightrope walk, especially when you can't exactly update to latest and greatest. This talk will explore the challenges and methods of maintaining multiple library versions across OS versions and trying to keep them secure and compatible. We'll explore attempts at FIPS compliance, backporting in the age of the CVE avalanche, and the struggle to keep things compatible when defaults get deprecated and broken. Finally, we’ll examine the hidden security risks businesses face when they bypass distro-packaged OpenSSL to build their own standalone versions.
— Compositor's note —
Computer Scientist and OpenSSL Maintainer at SUSE, working on Linux, protocols, and open-source software.